Perform IT Risk Analysis and Security Assessment. Conduct meetings with stakeholders. Manage third-party SOC audits and drive compliance throughout the year. Ensure compliance with frameworks such as NIST CSF, SSAE 18 SOC 1,2,3, PCI, ISO 27001 and internal policies. Prepare reports for management. Develop project plans and track audit deliverables. Identify, evaluate, investigate, and resolve compliance issues. Provide consultative services on controls for regulatory compliance. Conduct periodic reviews of Information Security risk and update policies and procedures. Execute security service strategy improvements. Requires strong knowledge of technology, regulations, information security, IT controls, and risk mitigation. IT graduates preferred.
What you'll do
Perform IT Risk Analysis and Security Assessment
Conduct kickoff, status, and closing meetings with stakeholders
Similar jobs
More roles worth a look
Related opportunities based on specialty and working model so candidates can keep momentum.
Manage third-party SOC audits as the key liaison for the organization, driving compliance throughout the year and managing the audit with the organization’s third-party auditor
Drive compliance across frameworks (e.g. NIST CSF, SSAE 18 SOC 1,2,3, PCI, ISO 27001, etc.) as well as internal policies and procedures
Assist in preparing reports to present to management
Develop project plans, tracking, and reporting, as well as drive stakeholders to completion for audit deliverables
Perform miscellaneous job-related duties as assigned
Ensure compliance issues are correctly identified, evaluated, investigated and resolved
Provide consultative services to business areas on the appropriate controls needed to ensure ongoing regulatory compliance
Conduct periodic reviews of Information Security risk within the policies, procedures and frameworks to identify opportunities for continuous improvement and ensure that the content remains accurate and current
Execute plans or roadmaps for security service strategy proposed improvements
Requirements
Strong experience and detailed understanding of technology, regulations, and information security or compliance management best practices
Ability to evaluate and recommend preventative and corrective controls to mitigate risk to the organization
Understanding of various components of an information security program
Technical aptitude, with the ability to effectively communicate with a working knowledge of all areas of IT controls